o A rule for the time service in the ipfw example was replaced by NTP

in r49600.  The "setup" keyword removed now as it is TCP specific.

Approved by:	wblock
This commit is contained in:
Maxim Konovalov 2017-01-04 18:42:26 +00:00
parent 7f8d53b90b
commit e4ced6076c
Notes: svn2git 2020-12-08 03:00:23 +00:00
svn path=/head/; revision=49796

View file

@ -2064,7 +2064,7 @@ pif="dc0" # interface name of NIC attached to Internet</programlisting>
&dollar;cmd 00250 allow icmp from any to any out via &dollar;pif keep-state
# Allow outbound NTP
&dollar;cmd 00260 allow udp from any to any 123 out via &dollar;pif setup keep-state
&dollar;cmd 00260 allow udp from any to any 123 out via &dollar;pif keep-state
# Allow outbound SSH
&dollar;cmd 00280 allow tcp from any to any 22 out via &dollar;pif setup keep-state